chiprook
← Security
SecuritySeptember 17, 2026, 19:58

TrustSink: How a Rogue External MFA Provider Steals Passwords

Varonis Threat Labs described the TrustSink technique: a high-privileged attacker registers a fake external authentication method (EAM) in Microsoft Entra and embeds a phishing password page into the legitimate login. The provider receives the password in plaintext and returns a valid signed token, so login completes without errors, and password changes do not remove the fake provider.

TrustSink: How a Rogue External MFA Provider Steals Passwords
#Microsoft#Entra#Varonis
Read next
Security

Sekoia uncovers Exvicy, a new ClickFix MaaS built on ErrTraffic code

Security

Cyberattack hits University of Munich, student data at risk

Security

TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8